The Tor Project

Last updated

The Tor Project, Inc.
FormationDecember 22, 2006
Founders
Type 501(c)(3)
20-8096820
PurposeTo advance human rights and freedoms by creating and deploying free and open source anonymity and privacy technologies, supporting their unrestricted availability and use, and furthering their scientific and popular understanding. [1]
Headquarters Winchester, Massachusetts, U.S.
Products
Executive Director
Isabela Bagueros [2]
Revenue (2020)
$4,400,782 [3]
Expenses (2020)$4,360,447 [3]
Website

The Tor Project, Inc. is a 501(c)(3) research-education [4] nonprofit organization based in Winchester, Massachusetts. [5] It is founded by computer scientists Roger Dingledine, Nick Mathewson, and five others. The Tor Project is primarily responsible for maintaining software for the Tor anonymity network. [6]

Contents

History

The Tor Project, Inc. was founded on December 22, 2006 [5] by computer scientists Roger Dingledine, Nick Mathewson and five others. The Electronic Frontier Foundation (EFF) acted as the Tor Project's fiscal sponsor in its early years, and early financial supporters of the Tor Project included the U.S. International Broadcasting Bureau, Internews, Human Rights Watch, the University of Cambridge, Google, and Netherlands-based Stichting NLnet. [7] [8] [9] [10] [11] [12]

In October 2014, the Tor Project hired the public relations firm Thomson Communications in order to improve its public image (particularly regarding the terms "Dark Net" and "hidden services") and to educate journalists about the technical aspects of Tor. [13]

In May 2015, the Tor Project ended the Tor Cloud Service. [14] [15]

In December 2015, the Tor Project announced that it had hired Shari Steele, former executive director of the Electronic Frontier Foundation, as its new executive director. Roger Dingledine, who had been acting as interim executive director since May 2015, remained at the Tor Project as a director and board member. [16] [17] [18] Later that month, the Tor Project announced that the Open Technology Fund would be sponsoring a bug bounty program that was coordinated by HackerOne. [19] [20] The program was initially invite-only and focuses on finding vulnerabilities that are specific to the Tor Project's applications. [19]

On May 25, 2016, Tor Project employee Jacob Appelbaum stepped down from his position; [21] [22] [23] this was announced on June 2 in a two-line statement by Tor. [24] Over the following days, allegations of sexual mistreatment were made public by several people. [23]

On July 13, 2016, the complete board of the Tor Project – Meredith Hoban Dunn, Ian Goldberg, Julius Mittenzwei, Rabbi Rob Thomas, Wendy Seltzer, Roger Dingledine and Nick Mathewson – was replaced with Matt Blaze, Cindy Cohn, Gabriella Coleman, Linus Nordberg, Megan Price and Bruce Schneier. [25] [26] [27] [28] A new anti-harassment policy has been approved by the new board, as well as a conflicts of interest policy, procedures for submitting complaints, and an internal complaint review process. [29] [30] The affair continues to be controversial, with considerable dissent within the Tor community. [31]

In 2020, due to the COVID-19 pandemic, the Tor project's core team let go of 13 employees, leaving a working staff of 22 people. [32]

Funding

As of 2012, 80% of the Tor Project's $2 million annual budget came from the United States government, with the U.S. State Department, the Broadcasting Board of Governors, and the National Science Foundation as major contributors, [33] "to aid democracy advocates in authoritarian states". [34] The Swedish government and other organizations provided the other 20%, including NGOs and thousands of individual sponsors. [10] [35] Dingledine said that the United States Department of Defense funds are more similar to a research grant than a procurement contract. Tor executive director Andrew Lewman said that even though it accepts funds from the U.S. federal government, the Tor service did not collaborate with the NSA to reveal identities of users. [36]

In June 2016, the Tor Project received an award from Mozilla's Open Source Support program (MOSS). The award was "to significantly enhance the Tor network's metrics infrastructure so that the performance and stability of the network can be monitored and improvements made as appropriate." [37]

Tools

Analytics for the Tor network, including graphs of its available bandwidth and estimated userbase. This is a great resource for researchers interested in detailed statistics about Tor.
a terminal (command line) application for monitoring and configuring Tor, intended for command-line enthusiasts and ssh connections. This functions much like top does for system usage, providing real time information on Tor's resource utilization and state.
Web-based protocol to learn about currently running Tor relays and bridges.
An open source tool that allows users to securely and anonymously share a file of any size.
a global observation network, monitoring network censorship, which aims to collect high-quality data using open methodologies, using Free and Open Source Software (FL/OSS) to share observations and data about the various types, methods, and amounts of network tampering in the world.
Tor for Android and iOS devices, in collaboration with The Guardian Project
a library for use by any Android application to route Internet traffic through Orbot/Tor.
helps circumvent censorship. Transforms the Tor traffic flow between the client and the bridge. This way, censors who monitor traffic between the client and the bridge will see innocent-looking transformed traffic instead of the actual Tor traffic.
Site providing an overview of the Tor network.
a discrete-event network simulator that runs the real Tor software as a plug-in. Shadow is open-source software that enables accurate, efficient, controlled, and repeatable Tor experimentation.
Python Library for writing scripts and applications that interact with Tor.
a live CD/USB distribution preconfigured so that everything is safely routed through Tor and leaves no trace on the local system.
free software and an open network that helps a user defend against traffic analysis, a form of network surveillance that threatens personal freedom and privacy, confidential business activities and relationships, and state security. The organization has also implemented the software in Rust named Arti. [38]
a customization of Mozilla Firefox which uses a Tor circuit for browsing anonymously and with other features consistent with the Tor mission.
A phone that routes its network traffic through tor network. Initially based on a CopperheadOS custom ROM prototype, [39] using Tor with Orbot and Tor Browser are supported by custom Android operating systems CalyxOS [40] [41] and DivestOS. [42] GrapheneOS supports using Orbot VPN [43] but not Tor Browser. [44]
Torbutton for Thunderbird and related *bird forks.
Python and Twisted event-based implementation of the Tor control protocol. Unit-tests, state and configuration abstractions, documentation. It is available on PyPI and in Debian. [45]

Recognition

In March 2011, the Tor Project received the Free Software Foundation's 2010 Award for Projects of Social Benefit. The citation read, "Using free software, Tor has enabled roughly 36 million people around the world to experience freedom of access and expression on the Internet while keeping them in control of their privacy and anonymity. Its network has proved pivotal in dissident movements in both Iran and more recently Egypt." [46]

In September 2012, the Tor Project received the 2012 EFF Pioneer Award, along with Jérémie Zimmermann and Andrew Huang. [47]

In November 2012, Foreign Policy magazine named Dingledine, Mathewson, and Syverson among its Top 100 Global Thinkers "for making the web safe for whistleblowers". [48]

In 2014, Roger Dingledine, Nick Mathewson and Paul Syverson received the USENIX Test of Time Award for their paper titled "Tor: The Second-Generation Onion Router", which was published in the Proceedings of the 13th USENIX Security Symposium, August 2004. [49]

In 2021, the Tor Project was awarded the Levchin Prize for real-world cryptography [50] .

Related Research Articles

<span class="mw-page-title-main">Onion routing</span> Technique for anonymous communication over a computer network

Onion routing is a technique for anonymous communication over a computer network. In an onion network, messages are encapsulated in layers of encryption, analogous to the layers of an onion. The encrypted data is transmitted through a series of network nodes called "onion routers," each of which "peels" away a single layer, revealing the data's next destination. When the final layer is decrypted, the message arrives at its destination. The sender remains anonymous because each intermediary knows only the location of the immediately preceding and following nodes. While onion routing provides a high level of security and anonymity, there are methods to break the anonymity of this technique, such as timing analysis.

<span class="mw-page-title-main">Jacob Appelbaum</span> American computer security researcher and journalist (born 1 April 1983)

Jacob Appelbaum is an American independent journalist, computer security researcher, artist, and hacker.

<span class="mw-page-title-main">Tor (network)</span> Free and open-source anonymity network based on onion routing

Tor is free and open-source software for enabling anonymous communication. It directs Internet traffic via a free, worldwide volunteer overlay network that consists of more than seven thousand relays.

<span class="mw-page-title-main">Noisebridge</span>

Noisebridge is an anarchistic maker and hackerspace located in San Francisco. It is inspired by the European hackerspaces Metalab in Vienna and c-base in Berlin. Noisebridge describes itself as "a space for sharing, creation, collaboration, research, development, mentoring, and learning". Outside of its headquarters, Noisebridge forms a wider international community. It was organized in 2007 and has had permanent facilities since 2008.

<span class="mw-page-title-main">Tails (operating system)</span> Linux distribution for anonymity and privacy

Tails, or "The Amnesic Incognito Live System", is a security-focused Debian-based Linux distribution aimed at preserving Internet privacy and anonymity. It connects to the Internet exclusively through the anonymity network Tor. The system is designed to be booted as a live DVD or live USB and never writes to the hard drive or SSD, leaving no digital footprint on the machine unless explicitly told to do so. It can also be run as a virtual machine, with some additional security risks.

<span class="mw-page-title-main">Ultrasurf</span>

UltraSurf is a freeware Internet censorship circumvention product created by UltraReach Internet Corporation. The software bypasses Internet censorship and firewalls using an HTTP proxy server, and employs encryption protocols for privacy.

<span class="mw-page-title-main">Orbot</span> Free software project to provide anonymity on the Internet from an Android smartphone

Orbot is a free proxy app that provides anonymity on the Internet for users of the Android and iOS operating systems. It allows traffic from apps such as web browsers, email clients, map programs, and others to be routed via the Tor network.

Mozilla is a free software community founded in 1998 by members of Netscape. The Mozilla community uses, develops, publishes and supports Mozilla products, thereby promoting exclusively free software and open standards, with only minor exceptions. The community is supported institutionally by the non-profit Mozilla Foundation and its tax-paying subsidiary, the Mozilla Corporation.

Flash proxy is a pluggable transport and proxy which runs in a web browser. Flash proxies are an Internet censorship circumvention tool which enables users to connect to the Tor anonymity network via a plethora of ephemeral browser-based proxy relays. The essential idea is that the IP addresses contingently used are changed faster than a censoring agency can detect, track, and block them. The Tor traffic is wrapped in a WebSocket format and disguised with an XOR cipher.

<span class="mw-page-title-main">Guardian Project (software)</span> Open source security software project

The Guardian Project is a global collective of software developers, designers, advocates, activists, and trainers who develop open-source mobile security software and operating system enhancements. They also create customized mobile devices to help individuals communicate more freely and protect themselves from intrusion and monitoring. The effort specifically focuses on users who live or work in high-risk situations and who often face constant surveillance and intrusion attempts into their mobile devices and communication streams.

<span class="mw-page-title-main">Whonix</span> Anonymous operating system

Whonix is a Linux distribution, based on Kicksecure OS, claimed to be security hardened by its developers. Its main goals are to provide strong privacy and anonymity on the Internet. The operating system consists of two virtual machines, a workstation and a Tor gateway running Debian. All communications are forced through Tor.

<span class="mw-page-title-main">Caspar Bowden</span>

Caspar Pemberton Scott Bowden was a British privacy advocate, formerly a chief privacy adviser at Microsoft. Styled as "an independent advocate for information privacy rights, and public understanding of privacy research in computer science", he was on the board of the Tor anonymity service. and a fellow of the British Computer Society. Having predicted US mass surveillance programmes such as PRISM from open sources, he gathered renewed attention after the Snowden leaks vindicated his warnings.

<span class="mw-page-title-main">Library Freedom Project</span>

The Library Freedom Project teaches librarians about surveillance threats, privacy rights, and digital tools to thwart surveillance. In 2015 the Project began an endeavour to place relays and, particularly, exit nodes of the Tor anonymity network in public libraries.

<span class="mw-page-title-main">Roger Dingledine</span> American computer scientist

Roger Dingledine is an American computer scientist known for having co-founded the Tor Project. A student of mathematics, computer science, and electrical engineering, Dingledine is also known by the pseudonym arma. As of December 2016, he continues in a leadership role with the Tor Project, as a project Leader, Director, and Research Director.

<span class="mw-page-title-main">Firefox Focus</span> Free and open-source privacy-focused web browser by Mozilla

Firefox Focus is a free and open-source privacy-focused mobile browser by Mozilla, based on Firefox. It is available for Android and iOS smartphones and tablets. Its predecessor, Focus by Firefox, was released in December 2015 as a tracker-blocking application which worked only in conjunction with the Safari mobile browser on iOS. It was developed into a minimalist web browser in 2016 but retained this background blocking functionality. The Android version of the browser was first released in June 2017 and was downloaded over one million times in the first month. As of January 2017, it was available in 27 languages. The version released for German-speaking countries has telemetry disabled and is named Firefox Klar to avoid ambiguity with the German news magazine FOCUS.

The Update Framework (TUF) is a software framework designed to protect mechanisms that automatically identify and download updates to software. TUF uses a series of roles and keys to provide a means to retain security, even when some keys or servers are compromised. It does this with a stated goal of requiring minimal changes and effort from repository administrators, software developers, and end users. In this way, it protects software repositories, which are an increasingly desirable target for hackers.

torservers.net is an independent network of non-profit organisations that provide nodes to the Tor anonymity network. The network started in June 2010 and currently transfers up to 7.4 GB/s (~59.2 Gb/s) of exit node traffic as of May 2022.

<span class="mw-page-title-main">Nick Mathewson</span> American computer scientist

Nick Mathewson is an American computer scientist and co-founder of The Tor Project. He, along with Roger Dingledine, began working on onion routing shortly after they graduated from Massachusetts Institute of Technology (MIT) in the early 2000s. He is also known by his pseudonym nickm. Mathewson and Dingledine were the focus of increased media attention after the leak of NSA's highly classified documents by Edward Snowden, and the subsequent public disclosure of the operation of XKeyscore, which targeted one of The Tor Project's onion servers along with Mixminion remailer which are both run at MIT.

<span class="mw-page-title-main">DivestOS</span> Android-based mobile operating system

DivestOS is an operating system based on the Android mobile platform. It is a soft fork of LineageOS that aims to increase security and privacy with support for end-of-life devices. As much as possible, it removes unnecessary proprietary Android components and includes only free-software.

References

  1. Tor Project. "Tor Project Mission Statement". Tor Project. Retrieved January 11, 2023.
  2. N/A, steph (April 23, 2018). "Announcing Tor's Next Executive Director: Isabela Bagueros". TorProject. Tor Project Blog. Retrieved December 26, 2018.
  3. 1 2 "Tor Project Form 990 2019" (PDF). Tor Project. July 8, 2021. Retrieved August 6, 2021.
  4. "The Tor Social Contract | Tor Project". blog.torproject.org. Retrieved February 2, 2023.
  5. 1 2 "The Tor Project, Inc. :: Massachusetts (US) :: OpenCorporates". OpenCorporates . December 22, 2006. Retrieved May 18, 2024.
  6. "Tor Project: People". The Tor Project, Inc. Retrieved July 7, 2021.
  7. "Tor Project Form 990 2008" (PDF). Tor Project. 2009. Retrieved August 30, 2014.
  8. "Tor Project Form 990 2007" (PDF). Tor Project. 2008. Retrieved August 30, 2014.
  9. "Tor Project Form 990 2009" (PDF). Tor Project. 2010. Retrieved August 30, 2014.
  10. 1 2 "Tor: Sponsors". Tor Project. Retrieved December 11, 2010.
  11. "The NLnet Foundation funds two projects". Torproject blog. June 6, 2008.
  12. Krebs, Brian (August 8, 2007). "Attacks Prompt Update for 'Tor' Anonymity Network". Washington Post . Retrieved October 27, 2007.
  13. "Can Tor solve its PR problem?". The Daily Dot. March 26, 2015. Retrieved April 19, 2015.
  14. "Tor Cloud"
  15. karsten (May 8, 2015). "Tor Cloud Service Ending; Many Ways Remain to Help Users Access an Uncensored Internet".
  16. "Tor Hires a New Leader to Help It Combat the War on Privacy". WIRED. Retrieved April 29, 2016.
  17. "Shari Steele named executive director of the Tor Project". SC Magazine. December 11, 2015. Retrieved April 29, 2016.
  18. "Roger Dingledine Becomes Interim Executive Director of the Tor Project | The Tor Blog". blog.torproject.org. Retrieved April 29, 2016.
  19. 1 2 Cox, Joseph (December 29, 2015). "The Tor Project Is Starting a Bug Bounty Program". Motherboard. Vice Media LLC. Retrieved February 14, 2016.
  20. Conditt, Jessica (December 31, 2015). "Tor plans to launch a bug bounty program". Engadget. AOL Inc. Retrieved February 14, 2016.
  21. ssteele (June 2, 2016). "Jacob Appelbaum leaves the Tor Project". The Tor Project, Inc. Retrieved June 4, 2016.
  22. Smith, Jack IV (June 4, 2016). "Jacob Appelbaum, Digital Rights Activist, Leaves Tor Amid Sexual Misconduct Allegations". Tech.Mic . Retrieved June 5, 2016.
  23. 1 2 Steele, Shari (June 4, 2016). "Statement". The Tor Project, Inc. Retrieved June 5, 2016.
  24. Cimpanu, Catalin (June 6, 2016). "Jacob Appelbaum Leaves Tor Project amid Multiple "Sexual Misconduct" Accusations: Tor Project leadership distances itself from Applebaum as the "sexual misconduct" accusations gain more ground". Softpedia. Retrieved June 5, 2016.
  25. Perlroth, Nicole (July 13, 2016). "Tor Project, a Digital Privacy Group, Reboots With New Board". The New York Times . Retrieved July 14, 2016.
  26. Farivar, Cyrus (July 13, 2016). "In wake of Appelbaum fiasco, Tor Project shakes up board of directors". arstechnica.com. Ars Technica . Retrieved July 14, 2016.
  27. "Tor Project installs new board of directors after Jacob Appelbaum controversy", Colin Lecher, July 13, 2016, The Verge
  28. "The Tor Project Elects New Board of Directors" Archived 2017-08-06 at the Wayback Machine , July 13th, 2016, Tor.org
  29. Stelle, Shari (July 27, 2016). "Statement". The Tor Project, Inc. Retrieved July 27, 2016.
  30. Farivar, Cyrus (July 27, 2016). "Tor inquiry: "Many people" reported being "humiliated" by Appelbaum: Going forward, group will now have a new anti-harassment policy, among other changes". Ars Technica. Retrieved July 27, 2016.
  31. Bernstein, Joseph (August 23, 2016). "video Tech Dissent And Distrust In Tor Community Following Jacob Appelbaum's Ouster: In the aftermath of the explosive allegations against its most famous advocate, and under new leadership, the Tor Project struggles to move on". BuzzFeedNews. Retrieved August 24, 2016.
  32. "COVID-19's impact on Tor | Tor Blog". blog.torproject.org. Retrieved April 20, 2020.
  33. McKim, Jenifer B. (March 8, 2012). "Privacy software, criminal use". The Boston Globe . Archived from the original on March 12, 2012.
  34. J. Appelbaum; A. Gibson; J. Goetz; V. Kabisch; L. Kampf; L. Ryge (July 3, 2014). "NSA targets the privacy-conscious". Panorama. Norddeutscher Rundfunk. Retrieved July 4, 2014.
  35. Fowler, Geoffrey A. (December 17, 2012). "Tor: an anonymous, and controversial, way to web-surf". Wall Street Journal . Retrieved May 19, 2013.
  36. Fung, Brian (September 6, 2013). "The feds pay for 60 percent of Tor's development. Can users trust it?". The Switch. Washington Post . Retrieved February 6, 2014.
  37. https://blog.mozilla.org/blog/2016/06/22/mozilla-awards-385000-to-open-source-projects-as-part-of-moss-mission-partners-program The Mozilla Blog. Retrieved 30 August 2016.
  38. nickm. "Arti 1.0.0 is released: Our Rust Tor implementation is ready for production use". Tor Blog. Retrieved October 1, 2022.
  39. Staff, Ars (November 22, 2016). "Tor phone is antidote to Google "hostility" over Android, says developer". Ars Technica. Archived from the original on August 13, 2022. Retrieved August 13, 2022.
  40. "Orbot". calyxos.org. Retrieved February 4, 2023.
  41. "Apps". calyxos.org. Retrieved February 4, 2023.
  42. "Recommended Apps - DivestOS Mobile". divestos.org. Retrieved February 4, 2023.
  43. "Frequently Asked Questions | GrapheneOS". grapheneos.org. Retrieved February 4, 2023.
  44. "Usage guide | GrapheneOS". grapheneos.org. Retrieved February 4, 2023.
  45. "Projects Overview". The Tor Project, Inc. Retrieved November 15, 2018. CC-BY icon.svg This article contains quotations from this source, which is available under the Creative Commons Attribution 3.0 Unported (CC BY 3.0) license.
  46. "2010 Free Software Awards announced". Free Software Foundation . Retrieved March 23, 2011.
  47. "EFF Pioneer Awards 2012". Electronic Frontier Foundation. September 20, 2012. Retrieved August 17, 2015.
  48. Wittmeyer, Alicia P.Q. (November 26, 2012). "The FP Top 100 Global Thinkers". Foreign Policy . Archived from the original on November 30, 2012. Retrieved November 28, 2012.
  49. "USENIX Test of Time Awards". USENIX. September 4, 2013. Retrieved August 29, 2015.
  50. "The Levchin Prize for Real-World Cryptography". Real World Crypto Symposium. International Association for Cryptologic Research. Retrieved April 9, 2024.